488 hack event(s)
Description of the event: Secured Finance’s fixed-rate lending protocol was exploited via an order-book accounting flaw that treated unfilled orders as filled and created invalid balances. Attackers used flash loans and self-trades to manipulate the current-block price and withdraw funds. Markets on Ethereum, Arbitrum, and Filecoin were paused. The team’s preliminary loss estimate is about $180,000; no recovery has been confirmed.
Amount of loss: $ 180000 Attack method: Flash Loan Price Manipulation
Description of the event: Reddio’s RedSonic Vault on Ethereum was exploited for about 9.25 ETH (~$22,800). After permissionlessly registering an stETH vault, the same stETH was counted in both the ETH vault and the stETH vault. The attacker used a flash loan to inflate the rsvETH share price, redeemed excess ETH, then redeemed rsvstETH to recover the same stETH.
Amount of loss: $ 22,800 Attack method: Smart Contract Vulnerability
Description of the event: Notional Finance’s legacy V1 Escrow contract was exploited. The attacker abused an unsafe uint128 cast in free-collateral valuation so that a fabricated liability of about 2^128 truncated to zero, bypassing solvency checks, minting fake fCash claims, and withdrawing about 69,257.37 DAI and 1,658,524.86 USDC (~$1.73M). The funds were swapped into roughly 689.2 ETH and deposited into Tornado Cash. The team paused the affected contract, said other user assets were not at risk, and is pursuing recovery.
Amount of loss: $ 1,730,000 Attack method: Smart Contract Vulnerability
Description of the event: The GebProxyActions contract was exploited due to missing caller access control in the quitSystem function. Victims had previously called it directly instead of via DSProxy delegatecall, setting ownsSAFE[safe] to the GebProxyActions contract. The attacker called GebProxyActions.quitSystem(manager, safe, dst) directly, bypassing GebSafeManager’s safeAllowed check and transferring collateral to themselves.
Amount of loss: $ 14,000 Attack method: Smart Contract Vulnerability
Description of the event: An attacker used a flash loan to execute large swaps on a Uniswap V3 pool and manipulate the spot price (slot0). This caused Float Protocol’s Hypervisor contracts to misprice LP shares. Because critical functions lacked TWAP/oracle validation and slippage protection, the attacker repeatedly deposited and withdrew at inflated share values, extracting about $28,000 (10.71 ETH).
Amount of loss: $ 28,000 Attack method: Flash Loan Price Manipulation
Description of the event: An attacker exploited a rounding/precision vulnerability in legacy Balancer V1 contracts. Using flash loans to compress WBTC reserves to near-zero, they minted a large amount of BPT with only 1 satoshi of WBTC and then proportionally exited to drain DPI, USDC, WETH and WBTC from the pool.
Amount of loss: $ 234,000 Attack method: Smart Contract Vulnerability
Description of the event: On August 23, 2026, Term Finance’s Strategy Vaults (Ethereum-based fixed-rate lending protocol by Term Labs) suffered a governance exploit. The attacker acquired majority voting power (100% on several USDC vaults, ~91% on the ETH Meta Vault), passed malicious proposals to disable the timelock and drain ~2,843 ETH and 1.68M USDC (later swapped to DAI), resulting in ~$8.5 million losses (about 68% of the vaults’ then-TVL).
Amount of loss: $ 8,500,000 Attack method: Governance Attack
Description of the event: On August 23, 2026, the Arrakis V1 / G-UNI ENS–WETH liquidity-manager vault (0x7c687f775a3b73bbab0e15832f24caab5d53bdde) was drained via Uniswap V3 spot-price manipulation. The attacker flash-loaned 1,800 WETH from Morpho Blue, skewed the pool’s instantaneous spot price, minted vault shares at the distorted valuation, restored the price, and burned the shares for a richer token mix, netting ≈2.94 WETH. Root cause: mint()/burn() valued the Uniswap V3 position off pool.slot0() with no TWAP or deviation guard (TWAP only protected rebalance()).
Amount of loss: $ 7,018 Attack method: Flashloan Price Manipulation
Description of the event: The USM protocol suffered an exploit due to a pricing logic flaw in the ethFromDefund() function within defund(). It uses the arithmetic mean of the current and estimated final FUM sell prices for a single redemption but lacks “split invariance.” Combined with the per-redemption state contraction (adjShrinkFactor) and integer rounding, an attacker used a flash loan to call fund() to manipulate internal pricing, then split the same FUM amount into 64 small defund() calls, extracting more ETH than a single large call and causing a loss of ~70.83 ETH.
Amount of loss: $ 136,000 Attack method: Smart Contract Vulnerability
Description of the event: Unistreets LaunchpadFactoryAuto contract on Ethereum was exploited via arbitrary calldata injection. The factory custodied all launched tokens’ Uniswap V4 LP NFTs; the attacker injected setApprovalForAll approval and burned multiple LP positions, draining liquidity for a loss of approximately $17,750.
Amount of loss: $ 17,750 Attack method: Smart Contract Vulnerability
Description of the event: On August 3, 2026, an unauthorized withdrawal of 673,011.56 USDC occurred from the RWA strategy linked to RISEx’s XLP vault due to a misconfiguration present since its July 13 deployment. The team detected it within minutes, patched it by 08:09 UTC, and fully compensated XLP depositors using a portion of July fees; the platform and other components continued operating normally.
Amount of loss: $ 673,011.56 Attack method: Smart Contract Vulnerability
Description of the event: The DeFi protocol Set Protocol (involving Index Coop’s ExchangeIssuance contract) was exploited due to insufficient state locking in the smart contract. The attacker used a malicious manager pre-issue hook to artificially inflate asset valuations (e.g., positionMultiplier), causing the contract to transfer excess assets based on falsified data, resulting in a loss of approximately $9,600.
Amount of loss: $ 9,600 Attack method: Smart Contract Vulnerability
Description of the event: The Projekt (GREEN/GOLD) reward vault on Ethereum was exploited. The attacker flash-loaned ~14K WETH from Morpho, pushed it into multiple Uniswap V2 memecoin pairs and used skim() to create fake “purchase” records. Exploiting the permissionless trackPurchase function (which only reads token balance deltas to size rewards without verifying actual ETH spent), they inflated reward allocations and drained ~301.7 ETH (~$560K) from the vault’s reward pool via massWithdraw.
Amount of loss: $ 560000 Attack method: Flash Loan Attack
Description of the event: On July 24, 2026, Lien Finance (an Ethereum DeFi structured products protocol) was exploited. The attacker abused a validation flaw in the exchangeEquivalentBonds function of the BondMakerCollateralizedEth contract (missing multiset integrity checks), minting unbacked bond tokens and draining approximately $542K USDC via OTC pools.
Amount of loss: $ 542,000 Attack method: Smart Contract Vulnerability
Description of the event: DeFi protocol BarnBridge suffered a governance attack on July 15, 2026. The attacker gained control of the DAO via a malicious governance proposal, upgraded the proxy contract to a malicious implementation, and drained approximately $776,000 USDC by exploiting pre-existing approvals from around 50 user addresses.
Amount of loss: $ 776,000 Attack method: Governance Attack
Description of the event: DeFi streaming payments protocol Drips Network was exploited on July 14, 2026. The attacker used an unsafe integer cast vulnerability (uint128 to int128) in the DaiDripsHub.give() function on Ethereum, causing a negative value to flip positive and reverse the transfer direction, draining 24,882.99 DAI (~$24,900) from the DaiReserve.
Amount of loss: $ 24,900 Attack method: Smart Contract Vulnerability
Description of the event: Chi Protocol (a DeFi stablecoin protocol issuing $USC backed by LSTs/LRTs on Ethereum) was exploited due to a logic error in the ArbitrageV5 contract’s burn() function. The attacker used a flash loan to buy heavily depegged $USC cheaply on a thin Uniswap V2 pool and burned it to redeem full-value collateral (weETH/stETH/WETH) at the hardcoded $1 peg, without the burn function checking the actual peg (unlike the mint function). This resulted in approximately $8,500 loss, nearly draining the protocol’s reserves.
Amount of loss: $ 8,500 Attack method: Smart Contract Logic Vulnerability
Description of the event: Lazy Summer Protocol (under Summer.fi) USDC vaults were exploited due to NAV/share price calculation flaw. The attacker used flash loans and pre-accumulated overvalued Silo tokens to inflate vault NAV (~9.5%), redeeming at inflated price and extracting ~$6.04M from other depositors.
Amount of loss: $ 6,040,000 Attack method: Smart Contract Vulnerability
Description of the event: Hinkal privacy DeFi protocol's Ethereum contract was exploited. The attacker used a "proofless deposit" vulnerability to drain approximately $820K USDC, then converted it to ETH and laundered via Tornado Cash and THORChain. The team paused contracts, limited the incident to one Ethereum pool, and committed to 1:1 user compensation.
Amount of loss: $ 820,000 Attack method: Smart Contract Vulnerability
Description of the event: Edel Finance lending protocol was exploited via wGOOGLx wrapped token exchange rate manipulation. The attacker used flash loans in repeated deposit/borrow loops to inflate wGOOGLx collateral value ~78x, then borrowed assets, creating ~$403K bad debt.
Amount of loss: $ 403,000 Attack method: Smart Contract Vulnerability